CVE-2018-11471: XSS
Published May 25, 2018
·Updated
Cockpit 0.5.5 has XSS via a collection, form, or region.
Affected Software
1 affected component
Getcockpit Cockpit=0.5.5
Event History
May 25, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11471?
CVE-2018-11471 is a vulnerability in Cockpit 0.5.5 that allows for XSS attacks through a collection, form, or region.
2
How severe is CVE-2018-11471?
CVE-2018-11471 has a severity rating of medium, with a score of 5.4.
3
How can I fix CVE-2018-11471?
To fix CVE-2018-11471, upgrade Cockpit to a version that is not affected by the vulnerability.
4
What is the Common Weakness Enumeration (CWE) for CVE-2018-11471?
The CWE for CVE-2018-11471 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
Where can I find more information about CVE-2018-11471?
More information about CVE-2018-11471 can be found at the following reference link: [GitHub - Cockpit-CMS-XSS-POC](https://github.com/nikhil1232/Cockpit-CMS-XSS-POC).